Non-Invasive Capture Nodes for Legacy Event Harvesting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Complex Event Processing (CEP) systems face challenges in harvesting simple events from legacy systems without requiring significant modifications, which poses risks and security concerns, as they often assume easy exposure of events for monitoring.
Innovation Solution
The system employs configurable capture node modules that can operate in non-invasive modes, such as packet sniffers or log file sniffers, allowing deployment without impacting the legacy system, and includes a heartbeat mechanism for reliability, with dynamic reconfiguration capabilities to minimize invasive interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If invasive capture node modules are used to harvest simple events from legacy systems, then the ability to detect complex events is improved, but the risk of adverse behavior changes and security risks increases
Solution Approach 1:
The patent introduces capture node modules as intermediary components that sit between the monitoring system and legacy systems. These capture nodes harvest simple events from legacy systems without requiring the legacy systems to be directly modified or exposed to the monitoring system, thus enabling event detection while maintaining security isolation and preventing adverse behavior changes in the legacy systems.
Solution Approach 2:
The monitoring system is segmented into distributed capture node modules that can be deployed independently on or near legacy systems. This segmentation allows the system to harvest events from multiple legacy systems without requiring centralized access or modification, reducing security risks while maintaining detection capabilities.
2Loss of information
If modifications are made to legacy systems to expose events for monitoring, then the ability to harvest simple events is improved, but the system complexity and deployment difficulty increase
Solution Approach 1:
The capture node modules serve as intermediaries that can be deployed on legacy systems without requiring modifications to the legacy systems themselves. The capture nodes harvest events from legacy systems through non-invasive means such as packet sniffing or log file analysis, eliminating the need to modify legacy system code or configuration while still enabling comprehensive event harvesting.
Solution Approach 2:
The capture node modules create copies of event data from legacy systems rather than requiring direct integration or modification. By copying events from legacy systems through non-invasive methods, the system enables event harvesting without altering the legacy systems, thus reducing deployment complexity.
3Ease of manufacture
If non-invasive capture node modules are used, then the ease of deployment is improved, but the quantity of harvestable simple events may be reduced
Solution Approach 1:
The capture node modules are designed with multi-functionality to harvest events from multiple sources and in multiple formats. They can capture events through various non-invasive methods including packet sniffing, log file analysis, and interface with event sources that already expose events. This universality ensures that a sufficient quantity of simple events can be harvested from diverse legacy systems without requiring invasive modifications.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A complex event processing system comprises a complex event processing engine (52) and an event harvesting system, wherein the event harvesting system is operable to monitor a computer network (10, 21, 22, 31, 32, 33), generate simple event reports in response to the result of monitoring the network and pass these to the complex event processing engine for processing. The event harvesting system comprises a central configuration control module (51, 53) and a plurality of capture node modules (41, 42) each of which is operatively connected to the central configuration control module. Each capture node module is operable to receive configuration instructions from the central configuration control module to determine what simple event reports are to be generated by the module and in response to what conditions detected on the monitored computer network. The central configuration control module includes an interface (51 ) in the form of a web server for receiving configuration instructions from a user of the system and for processing these configuration instructions and sending them to a specified capture node module for causing the module to operate in accordance with the specified configuration instructions.